Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: Virtumonde

  1. #1
    Junior Member
    Join Date
    Feb 2009
    Posts
    11

    Default Virtumonde

    Problems with this bad boy yet again.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:39:14 PM, on 3/7/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\DOCUME~1\Amiee\LOCALS~1\Temp\RtkBtMnt.exe
    C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {070547D8-462D-4EA5-8F21-6C3F091E58CF} - (no file)
    O2 - BHO: (no name) - {18936674-1CB3-4F4F-82C9-095F8446108D} - (no file)
    O2 - BHO: (no name) - {29BDA8BF-5984-4E22-AF97-43830CA46962} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5737F430-A65E-4E72-87E6-A7970F25A061} - (no file)
    O2 - BHO: {f78b49de-0148-4c58-b1c4-96d7f87c13b6} - {6b31c78f-7d69-4c1b-85c4-8410ed94b87f} - C:\WINDOWS\system32\biadyi.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: (no name) - {d1b951a2-6748-44bc-8793-269e233ece52} - C:\WINDOWS\system32\zibuyubo.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: (no name) - {E57B841E-5469-4393-A139-3E7043EA973A} - (no file)
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\WINDOWS\PLFSet.dll,PLFDefSetting
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [voduwakuso] Rundll32.exe "C:\WINDOWS\system32\jutepeso.dll",s
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [voduwakuso] Rundll32.exe "C:\WINDOWS\system32\jutepeso.dll",s (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [voduwakuso] Rundll32.exe "C:\WINDOWS\system32\jutepeso.dll",s (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1211556379173
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1211556454969
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSC...ws-i586-jc.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{31CE2B33-6824-4BF1-8F53-2EDB8B51F57B}: NameServer = 69.78.96.14 66.174.92.14
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\kapekabo.dll biadyi.dll c:\windows\system32\tebudati.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O20 - Winlogon Notify: cbXQKBRJ - C:\WINDOWS\
    O20 - Winlogon Notify: ssqRhhFx - C:\WINDOWS\
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\tebudati.dll (file missing)
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\tebudati.dll (file missing)
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    O23 - Service: Google Update Service (gupdate1c98babdb7847b2) (gupdate1c98babdb7847b2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 9462 bytes

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi CynicalFelidae

    We will begin with ComboFix.

    Please download ComboFix from one of these locations:

    Link 1
    Link 2
    Link 3

    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

      We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:

      1. Run Spybot-S&D in Advanced Mode.
      2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
      3. On the left hand side, Click on Tools
      4. Then click on the Resident Icon in the List
      5. Uncheck "Resident TeaTimer" and OK any prompts.
      6. Restart your computer.


    • Double click on ComboFix.exe & follow the prompts.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



    Click on Yes, to continue scanning for malware.

    When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.

    This tool is not a toy and not for everyday use.
    ComboFix SHOULD NOT be used unless requested by a forum helper


    If you need help, see this link:
    http://www.bleepingcomputer.com/comb...o-use-combofix
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Feb 2009
    Posts
    11

    Default

    the combofix log:

    ComboFix 09-03-06.02 - Amiee 2009-03-08 19:16:33.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1791.1318 [GMT -5:00]
    Running from: c:\documents and settings\Amiee\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
    FW: COMODO Firewall *enabled*
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\argpep.dll
    c:\windows\system32\biadyi.dll
    c:\windows\system32\drivers\seneka.sys
    c:\windows\system32\drivers\senekaewqwmnrj.sys
    c:\windows\system32\genahowa.dll
    c:\windows\system32\ivayoyot.ini
    c:\windows\system32\kapekabo.dll
    c:\windows\system32\senekaaxfkdqxm.dat
    c:\windows\system32\senekalespwmet.dll
    c:\windows\system32\senekankfpqcxu.dll
    c:\windows\system32\senekankoobrft.dat
    c:\windows\system32\senekasipfviqx.dll
    c:\windows\system32\vuzrpg.dll
    c:\windows\system32\yadihoni.dll
    c:\windows\system32\zefumiwu.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_SENEKA


    ((((((((((((((((((((((((( Files Created from 2009-02-09 to 2009-03-09 )))))))))))))))))))))))))))))))
    .

    2009-03-08 15:01 . 2009-03-08 15:01 10,240 --a------ c:\windows\instsp1.exe
    2009-03-07 12:12 . 2009-03-07 12:12 <DIR> d-------- c:\program files\COMODO
    2009-03-07 12:12 . 2009-03-07 17:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Comodo
    2009-03-07 12:12 . 2009-03-07 12:12 155,384 --a------ c:\windows\system32\guard32.dll
    2009-03-07 12:12 . 2009-03-07 12:12 110,992 --a------ c:\windows\system32\drivers\cmdguard.sys
    2009-03-07 12:12 . 2009-03-07 12:12 24,336 --a------ c:\windows\system32\drivers\cmdhlp.sys
    2009-03-07 11:27 . 2009-03-07 11:40 324 --a------ c:\windows\wininit.ini
    2009-02-21 15:29 . 2009-02-21 15:29 <DIR> d-------- c:\program files\AGD Interactive
    2009-02-21 13:12 . 2009-02-21 13:12 <DIR> d-------- c:\program files\IA
    2009-02-10 13:15 . 2009-03-07 21:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\Google Updater

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-08 20:01 84,992 --sha-w c:\windows\system32\toturobe.dll
    2009-03-08 20:01 79,872 --sha-w c:\windows\system32\dinizuha.dll
    2009-03-08 08:01 84,992 --sha-w c:\windows\system32\zelayira.dll
    2009-03-08 08:01 79,872 ------w c:\windows\system32\toyoyavi.dll
    2009-03-07 16:40 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-03-06 02:06 --------- d-----w c:\program files\SpywareBlaster
    2009-03-03 17:02 --------- d-----w c:\program files\World of Warcraft
    2009-02-26 19:32 --------- d-----w c:\program files\Microsoft Silverlight
    2009-02-15 05:49 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-02-15 05:48 --------- d-----w c:\program files\Spybot - Search & Destroy
    2009-02-12 03:41 --------- d-----w c:\program files\Google
    2009-02-10 19:19 --------- d-----w c:\program files\Picasa2
    2009-02-08 13:47 410,984 ----a-w c:\windows\system32\deploytk.dll
    2009-02-08 13:47 --------- d-----w c:\program files\Java
    2009-02-07 15:35 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
    2009-02-04 05:14 --------- d-----w c:\program files\Trend Micro
    2009-02-04 05:13 --------- d-----w c:\program files\ERUNT
    2009-02-01 17:14 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
    2009-02-01 17:14 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
    2009-02-01 17:14 10,520 ----a-w c:\windows\system32\avgrsstx.dll
    2009-01-10 19:07 --------- d-----w c:\documents and settings\Amiee\Application Data\Winamp
    2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
    1601-01-01 00:12 47,616 --sha-w c:\windows\system32\jutepeso.dll
    1601-01-01 00:12 47,616 --sha-w c:\windows\system32\zibuyubo.dll
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-02-07_ 9.52.12.12 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\3-7-2009\ERDNT.EXE
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-10-2009\ERDNT.EXE
    + 2009-02-10 15:51:17 6,946,816 ----a-w c:\windows\ERDNT\AutoBackup\2-10-2009\Users\00000001\NTUSER.DAT
    + 2009-02-10 15:51:17 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-10-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-11-2009\ERDNT.EXE
    + 2009-02-11 16:42:59 6,946,816 ----a-w c:\windows\ERDNT\AutoBackup\2-11-2009\Users\00000001\NTUSER.DAT
    + 2009-02-11 16:42:59 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-11-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-12-2009\ERDNT.EXE
    + 2009-02-12 15:38:09 6,946,816 ----a-w c:\windows\ERDNT\AutoBackup\2-12-2009\Users\00000001\NTUSER.DAT
    + 2009-02-12 15:38:10 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-12-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-13-2009\ERDNT.EXE
    + 2009-02-13 14:02:06 6,946,816 ----a-w c:\windows\ERDNT\AutoBackup\2-13-2009\Users\00000001\NTUSER.DAT
    + 2009-02-13 14:02:06 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-13-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-14-2009\ERDNT.EXE
    + 2009-02-14 13:06:50 6,946,816 ----a-w c:\windows\ERDNT\AutoBackup\2-14-2009\Users\00000001\NTUSER.DAT
    + 2009-02-14 13:06:51 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-14-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-15-2009\ERDNT.EXE
    + 2009-02-15 14:22:22 7,020,544 ----a-w c:\windows\ERDNT\AutoBackup\2-15-2009\Users\00000001\NTUSER.DAT
    + 2009-02-15 14:22:23 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-15-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-16-2009\ERDNT.EXE
    + 2009-02-16 14:23:45 7,032,832 ----a-w c:\windows\ERDNT\AutoBackup\2-16-2009\Users\00000001\NTUSER.DAT
    + 2009-02-16 14:23:45 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-16-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-17-2009\ERDNT.EXE
    + 2009-02-17 17:50:40 7,036,928 ----a-w c:\windows\ERDNT\AutoBackup\2-17-2009\Users\00000001\NTUSER.DAT
    + 2009-02-17 17:50:40 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-17-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-18-2009\ERDNT.EXE
    + 2009-02-18 12:01:21 7,036,928 ----a-w c:\windows\ERDNT\AutoBackup\2-18-2009\Users\00000001\NTUSER.DAT
    + 2009-02-18 12:01:21 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-18-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-19-2009\ERDNT.EXE
    + 2009-02-19 12:20:07 7,036,928 ----a-w c:\windows\ERDNT\AutoBackup\2-19-2009\Users\00000001\NTUSER.DAT
    + 2009-02-19 12:20:08 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-19-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-20-2009\ERDNT.EXE
    + 2009-02-20 14:02:03 7,053,312 ----a-w c:\windows\ERDNT\AutoBackup\2-20-2009\Users\00000001\NTUSER.DAT
    + 2009-02-20 14:02:03 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-20-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-21-2009\ERDNT.EXE
    + 2009-02-21 14:10:36 7,061,504 ----a-w c:\windows\ERDNT\AutoBackup\2-21-2009\Users\00000001\NTUSER.DAT
    + 2009-02-21 14:10:36 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-21-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-22-2009\ERDNT.EXE
    + 2009-02-22 14:41:32 7,139,328 ----a-w c:\windows\ERDNT\AutoBackup\2-22-2009\Users\00000001\NTUSER.DAT
    + 2009-02-22 14:41:32 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-22-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-23-2009\ERDNT.EXE
    + 2009-02-23 16:00:55 7,139,328 ----a-w c:\windows\ERDNT\AutoBackup\2-23-2009\Users\00000001\NTUSER.DAT
    + 2009-02-23 16:00:55 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-23-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-24-2009\ERDNT.EXE
    + 2009-02-24 07:58:07 7,168,000 ----a-w c:\windows\ERDNT\AutoBackup\2-24-2009\Users\00000001\NTUSER.DAT
    + 2009-02-24 07:58:08 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-24-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-25-2009\ERDNT.EXE
    + 2009-02-25 14:38:26 7,172,096 ----a-w c:\windows\ERDNT\AutoBackup\2-25-2009\Users\00000001\NTUSER.DAT
    + 2009-02-25 14:38:27 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-25-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-26-2009\ERDNT.EXE
    + 2009-02-26 15:21:18 7,241,728 ----a-w c:\windows\ERDNT\AutoBackup\2-26-2009\Users\00000001\NTUSER.DAT
    + 2009-02-26 15:21:18 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-26-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-27-2009\ERDNT.EXE
    + 2009-02-27 15:07:30 7,241,728 ----a-w c:\windows\ERDNT\AutoBackup\2-27-2009\Users\00000001\NTUSER.DAT
    + 2009-02-27 15:07:30 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-27-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-28-2009\ERDNT.EXE
    + 2009-02-28 15:15:21 7,241,728 ----a-w c:\windows\ERDNT\AutoBackup\2-28-2009\Users\00000001\NTUSER.DAT
    + 2009-02-28 15:15:21 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-28-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-8-2009\ERDNT.EXE
    + 2009-02-08 11:51:59 6,946,816 ----a-w c:\windows\ERDNT\AutoBackup\2-8-2009\Users\00000001\NTUSER.DAT
    + 2009-02-08 11:51:59 12,288 ----a-w c:\windows\ERDNT\AutoBackup\2-8-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-9-2009\ERDNT.EXE
    + 2009-02-09 16:44:46 6,946,816 ----a-w c:\windows\ERDNT\AutoBackup\2-9-2009\Users\00000001\NTUSER.DAT
    + 2009-02-09 16:44:46 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2-9-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-08\ERDNT.EXE
    + 2009-03-09 00:21:38 7,307,264 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-08\Users\00000001\NTUSER.DAT
    + 2009-03-09 00:21:39 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-08\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-1-2009\ERDNT.EXE
    + 2009-03-01 15:36:49 7,241,728 ----a-w c:\windows\ERDNT\AutoBackup\3-1-2009\Users\00000001\NTUSER.DAT
    + 2009-03-01 15:36:49 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-1-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-2-2009\ERDNT.EXE
    + 2009-03-02 16:24:48 7,241,728 ----a-w c:\windows\ERDNT\AutoBackup\3-2-2009\Users\00000001\NTUSER.DAT
    + 2009-03-02 16:24:48 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-2-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-3-2009\ERDNT.EXE
    + 2009-03-03 15:04:59 7,241,728 ----a-w c:\windows\ERDNT\AutoBackup\3-3-2009\Users\00000001\NTUSER.DAT
    + 2009-03-03 15:04:59 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-3-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-4-2009\ERDNT.EXE
    + 2009-03-04 15:03:28 7,241,728 ----a-w c:\windows\ERDNT\AutoBackup\3-4-2009\Users\00000001\NTUSER.DAT
    + 2009-03-04 15:03:29 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-4-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-5-2009\ERDNT.EXE
    + 2009-03-05 15:11:33 7,241,728 ----a-w c:\windows\ERDNT\AutoBackup\3-5-2009\Users\00000001\NTUSER.DAT
    + 2009-03-05 15:11:34 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-5-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-6-2009\ERDNT.EXE
    + 2009-03-06 13:40:49 7,282,688 ----a-w c:\windows\ERDNT\AutoBackup\3-6-2009\Users\00000001\NTUSER.DAT
    + 2009-03-06 13:40:50 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-6-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-7-2009\ERDNT.EXE
    + 2009-03-07 13:14:51 7,290,880 ----a-w c:\windows\ERDNT\AutoBackup\3-7-2009\Users\00000001\NTUSER.DAT
    + 2009-03-07 13:14:51 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-7-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-8-2009\ERDNT.EXE
    + 2009-03-08 07:02:14 7,307,264 ----a-w c:\windows\ERDNT\AutoBackup\3-8-2009\Users\00000001\NTUSER.DAT
    + 2009-03-08 07:02:14 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-8-2009\Users\00000002\UsrClass.dat
    - 2005-10-21 02:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
    + 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
    - 2005-10-21 02:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
    + 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
    + 2008-10-16 20:38:34 124,928 -c----w c:\windows\ie7updates\KB961260-IE7\advpack.dll
    + 2008-10-16 20:38:34 347,136 -c----w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
    + 2008-10-16 20:38:34 214,528 -c----w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
    + 2008-10-16 20:38:35 133,120 -c----w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
    + 2008-10-16 20:38:35 63,488 -c----w c:\windows\ie7updates\KB961260-IE7\icardie.dll
    + 2008-10-16 13:11:09 70,656 -c----w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
    + 2008-10-16 20:38:35 153,088 -c----w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
    + 2008-10-16 20:38:35 230,400 -c----w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
    + 2008-10-15 07:04:53 161,792 -c----w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
    + 2008-10-16 20:38:35 383,488 -c----w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
    + 2008-10-16 20:38:35 384,512 -c----w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
    + 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
    + 2008-10-16 20:38:37 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
    + 2008-10-16 20:38:37 267,776 -c----w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
    + 2008-10-16 13:11:09 13,824 -c----w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
    + 2008-10-15 07:06:26 633,632 -c----w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
    + 2008-10-16 20:38:37 27,648 -c----w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
    + 2008-10-16 20:38:37 459,264 -c----w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
    + 2008-10-16 20:38:37 52,224 -c----w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
    + 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
    + 2008-10-16 20:38:38 477,696 -c----w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
    + 2008-10-16 20:38:38 193,024 -c----w c:\windows\ie7updates\KB961260-IE7\msrating.dll
    + 2008-10-16 20:38:39 671,232 -c----w c:\windows\ie7updates\KB961260-IE7\mstime.dll
    + 2008-10-16 20:38:39 102,912 -c----w c:\windows\ie7updates\KB961260-IE7\occache.dll
    + 2008-10-16 20:38:39 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
    + 2007-03-06 01:22:41 213,216 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
    + 2008-10-16 20:38:39 105,984 -c----w c:\windows\ie7updates\KB961260-IE7\url.dll
    + 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
    + 2008-10-16 20:38:39 233,472 -c----w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
    + 2008-10-16 20:38:40 826,368 -c----w c:\windows\ie7updates\KB961260-IE7\wininet.dll
    + 2009-02-10 18:18:08 363,246 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ARPPRODUCTICON.exe
    + 2009-02-10 18:18:09 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    + 2009-02-10 18:18:09 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    + 2009-02-10 18:18:09 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2009-02-10 18:18:09 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2009-02-10 18:18:09 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
    - 2009-01-14 02:49:15 593,920 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
    + 2009-02-11 06:51:34 593,920 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
    - 2009-01-14 02:49:15 12,288 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    + 2009-02-11 06:51:34 12,288 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2009-01-14 02:49:15 86,016 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
    + 2009-02-11 06:51:34 86,016 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
    - 2009-01-14 02:49:15 135,168 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
    + 2009-02-11 06:51:34 135,168 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2009-01-14 02:49:15 11,264 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    + 2009-02-11 06:51:34 11,264 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2009-01-14 02:49:15 27,136 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    + 2009-02-11 06:51:34 27,136 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    - 2009-01-14 02:49:15 4,096 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2009-02-11 06:51:34 4,096 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    - 2009-01-14 02:49:16 794,624 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
    + 2009-02-11 06:51:35 794,624 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
    - 2009-01-14 02:49:15 249,856 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
    + 2009-02-11 06:51:34 249,856 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
    - 2009-01-14 02:49:15 61,440 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
    + 2009-02-11 06:51:34 61,440 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
    - 2009-01-14 02:49:16 23,040 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    + 2009-02-11 06:51:35 23,040 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    - 2009-01-14 02:49:14 286,720 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    + 2009-02-11 06:51:34 286,720 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    - 2009-01-14 02:49:14 409,600 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2009-02-11 06:51:34 409,600 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    - 2000-08-31 14:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
    + 2000-08-31 13:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
    - 2000-08-31 14:00:00 161,792 ----a-w c:\windows\SWREG.exe
    + 2000-08-31 13:00:00 161,792 ----a-w c:\windows\SWREG.exe
    - 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll
    + 2008-12-20 23:15:11 124,928 ----a-w c:\windows\system32\advpack.dll
    - 2008-05-23 16:04:08 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2009-03-08 16:04:37 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
    - 2008-05-23 16:04:08 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    + 2009-03-08 16:04:37 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    - 2008-05-23 16:04:08 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    + 2009-03-08 16:04:37 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    - 2008-10-16 20:38:34 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
    + 2008-12-20 23:15:11 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
    - 2008-10-16 20:38:34 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
    + 2008-12-20 23:15:12 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
    - 2008-10-16 20:38:34 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
    + 2008-12-20 23:15:13 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
    - 2008-10-16 20:38:35 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
    + 2008-12-20 23:15:13 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
    - 2008-10-16 20:38:35 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
    + 2008-12-20 23:15:13 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
    - 2008-10-16 13:11:09 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
    + 2008-12-19 09:10:15 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
    - 2008-10-16 20:38:35 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
    + 2008-12-20 23:15:14 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
    - 2008-10-16 20:38:35 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
    + 2008-12-20 23:15:14 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
    - 2008-10-15 07:04:53 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
    + 2008-12-19 05:23:56 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
    - 2008-10-16 20:38:35 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
    + 2008-12-20 23:15:15 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
    - 2008-10-16 20:38:35 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
    + 2008-12-20 23:15:16 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
    - 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
    + 2008-12-20 23:15:21 6,066,688 -c----w c:\windows\system32\dllcache\ieframe.dll
    - 2008-10-16 20:38:37 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
    + 2008-12-20 23:15:21 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
    - 2008-10-16 20:38:37 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
    + 2008-12-20 23:15:22 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
    - 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
    + 2008-12-19 09:10:15 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
    - 2008-10-15 07:06:26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe
    + 2008-12-19 05:25:25 634,024 -c----w c:\windows\system32\dllcache\iexplore.exe
    - 2008-10-16 20:38:37 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
    + 2008-12-20 23:15:23 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
    - 2008-10-16 20:38:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
    + 2008-12-20 23:15:23 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
    - 2008-10-16 20:38:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
    + 2008-12-20 23:15:24 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
    - 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll
    + 2009-01-17 03:35:14 3,594,752 -c----w c:\windows\system32\dllcache\mshtml.dll
    - 2008-10-16 20:38:38 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
    + 2008-12-20 23:15:30 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
    - 2008-10-16 20:38:38 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
    + 2008-12-20 23:15:31 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
    - 2008-10-16 20:38:39 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
    + 2008-12-20 23:15:32 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
    - 2008-10-16 20:38:39 102,912 -c----w c:\windows\system32\dllcache\occache.dll
    + 2008-12-20 23:15:38 102,912 -c----w c:\windows\system32\dllcache\occache.dll
    - 2008-10-16 20:38:39 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
    + 2008-12-20 23:15:38 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
    + 2008-06-17 19:02:19 8,461,312 -c----w c:\windows\system32\dllcache\shell32.dll
    - 2008-10-16 20:38:39 105,984 -c----w c:\windows\system32\dllcache\url.dll
    + 2008-12-20 23:15:39 105,984 -c----w c:\windows\system32\dllcache\url.dll
    - 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll
    + 2008-12-20 23:15:40 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll
    - 2008-10-16 20:38:39 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
    + 2008-12-20 23:15:40 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
    - 2008-10-16 20:38:40 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
    + 2008-12-20 23:15:41 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
    + 2009-03-07 17:12:00 80,400 ----a-w c:\windows\system32\drivers\inspect.sys
    - 2008-10-16 20:38:34 347,136 ----a-w c:\windows\system32\dxtmsft.dll
    + 2008-12-20 23:15:12 347,136 ----a-w c:\windows\system32\dxtmsft.dll
    - 2008-10-16 20:38:34 214,528 ----a-w c:\windows\system32\dxtrans.dll
    + 2008-12-20 23:15:13 214,528 ----a-w c:\windows\system32\dxtrans.dll
    - 2008-10-16 20:38:35 133,120 ----a-w c:\windows\system32\extmgr.dll
    + 2008-12-20 23:15:13 133,120 ----a-w c:\windows\system32\extmgr.dll
    - 2008-10-16 20:38:35 63,488 ----a-w c:\windows\system32\icardie.dll
    + 2008-12-20 23:15:13 63,488 ----a-w c:\windows\system32\icardie.dll
    - 2008-10-16 13:11:09 70,656 ----a-w c:\windows\system32\ie4uinit.exe
    + 2008-12-19 09:10:15 70,656 ----a-w c:\windows\system32\ie4uinit.exe
    - 2008-10-16 20:38:35 153,088 ----a-w c:\windows\system32\ieakeng.dll
    + 2008-12-20 23:15:14 153,088 ----a-w c:\windows\system32\ieakeng.dll
    - 2008-10-16 20:38:35 230,400 ----a-w c:\windows\system32\ieaksie.dll
    + 2008-12-20 23:15:14 230,400 ----a-w c:\windows\system32\ieaksie.dll
    - 2008-10-15 07:04:53 161,792 ----a-w c:\windows\system32\ieakui.dll
    + 2008-12-19 05:23:56 161,792 ----a-w c:\windows\system32\ieakui.dll
    - 2008-10-16 20:38:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll
    + 2008-12-20 23:15:15 383,488 ----a-w c:\windows\system32\ieapfltr.dll
    - 2008-10-16 20:38:35 384,512 ----a-w c:\windows\system32\iedkcs32.dll
    + 2008-12-20 23:15:16 384,512 ----a-w c:\windows\system32\iedkcs32.dll
    - 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\system32\ieframe.dll
    + 2008-12-20 23:15:21 6,066,688 ----a-w c:\windows\system32\ieframe.dll
    - 2008-10-16 20:38:37 44,544 ----a-w c:\windows\system32\iernonce.dll
    + 2008-12-20 23:15:21 44,544 ----a-w c:\windows\system32\iernonce.dll
    - 2008-10-16 20:38:37 267,776 ----a-w c:\windows\system32\iertutil.dll
    + 2008-12-20 23:15:22 267,776 ----a-w c:\windows\system32\iertutil.dll
    - 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe
    + 2008-12-19 09:10:15 13,824 ----a-w c:\windows\system32\ieudinit.exe
    + 2009-02-08 13:47:45 144,792 ----a-w c:\windows\system32\java.exe
    + 2009-02-08 13:47:45 144,792 ----a-w c:\windows\system32\javaw.exe
    + 2009-02-08 13:47:45 148,888 ----a-w c:\windows\system32\javaws.exe
    - 2008-10-16 20:38:37 27,648 ----a-w c:\windows\system32\jsproxy.dll
    + 2008-12-20 23:15:23 27,648 ----a-w c:\windows\system32\jsproxy.dll
    - 2008-10-16 20:38:37 459,264 ----a-w c:\windows\system32\msfeeds.dll
    + 2008-12-20 23:15:23 459,264 ----a-w c:\windows\system32\msfeeds.dll
    - 2008-10-16 20:38:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
    + 2008-12-20 23:15:24 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
    - 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll
    + 2009-01-17 03:35:14 3,594,752 ----a-w c:\windows\system32\mshtml.dll
    - 2008-10-16 20:38:38 477,696 ----a-w c:\windows\system32\mshtmled.dll
    + 2008-12-20 23:15:30 477,696 ----a-w c:\windows\system32\mshtmled.dll
    - 2008-10-16 20:38:38 193,024 ----a-w c:\windows\system32\msrating.dll
    + 2008-12-20 23:15:31 193,024 ----a-w c:\windows\system32\msrating.dll
    - 2008-10-16 20:38:39 671,232 ----a-w c:\windows\system32\mstime.dll
    + 2008-12-20 23:15:32 671,232 ----a-w c:\windows\system32\mstime.dll
    - 2008-10-16 20:38:39 102,912 ----a-w c:\windows\system32\occache.dll
    + 2008-12-20 23:15:38 102,912 ----a-w c:\windows\system32\occache.dll
    - 2009-02-07 15:12:24 63,590 ----a-w c:\windows\system32\perfc009.dat
    + 2009-03-08 16:09:21 63,590 ----a-w c:\windows\system32\perfc009.dat
    - 2009-02-07 15:12:24 404,536 ----a-w c:\windows\system32\perfh009.dat
    + 2009-03-08 16:09:21 404,536 ----a-w c:\windows\system32\perfh009.dat
    - 2008-10-16 20:38:39 44,544 ----a-w c:\windows\system32\pngfilt.dll
    + 2008-12-20 23:15:38 44,544 ----a-w c:\windows\system32\pngfilt.dll
    - 2008-04-14 00:12:05 8,461,312 ----a-w c:\windows\system32\shell32.dll
    + 2008-06-17 19:02:19 8,461,312 ----a-w c:\windows\system32\shell32.dll
    - 2007-11-30 12:39:22 17,272 ----a-w c:\windows\system32\spmsg.dll
    + 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll
    - 2008-10-16 20:38:39 105,984 ----a-w c:\windows\system32\url.dll
    + 2008-12-20 23:15:39 105,984 ----a-w c:\windows\system32\url.dll
    - 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\system32\urlmon.dll
    + 2008-12-20 23:15:40 1,160,192 ----a-w c:\windows\system32\urlmon.dll
    - 2008-10-16 20:38:39 233,472 ----a-w c:\windows\system32\webcheck.dll
    + 2008-12-20 23:15:40 233,472 ----a-w c:\windows\system32\webcheck.dll
    + 2009-03-09 00:20:47 16,384 ----atw c:\windows\temp\Perflib_Perfdata_278.dat
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1b951a2-6748-44bc-8793-269e233ece52}]
    47616 --ahs---- c:\windows\system32\zibuyubo.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-23 8433664]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-23 81920]
    "PLFSet"="c:\windows\PLFSet.dll" [2007-04-24 45056]
    "RoxioDragToDisc"="c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2004-06-24 1691648]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-01 1601304]
    "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
    "voduwakuso"="c:\windows\system32\jutepeso.dll" [ 47616]
    "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-03-07 1851128]
    "70f5d722"="c:\windows\system32\toyoyavi.dll" [2009-03-08 79872]
    "nwiz"="nwiz.exe" [2007-07-23 c:\windows\system32\nwiz.exe]
    "RTHDCPL"="RTHDCPL.EXE" [2007-07-23 c:\windows\RTHDCPL.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

    c:\documents and settings\Amiee\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
    "{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\toturobe.dll" [2009-03-08 84992]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\toturobe.dll [2009-03-08 84992]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-02-01 12:14 10520 c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\system32\kapekabo.dll c:\windows\system32\toturobe.dll
    "LoadAppInit_DLLs"=1 (0x1)

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ scecli c:\windows\system32\kapekabo.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
    backup=c:\windows\pss\Bluetooth.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
    "c:\\WINDOWS\\explorer.exe"=

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-23 325128]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-05-23 107272]
    R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-03-07 110992]
    R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-03-07 24336]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-06 903960]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-06 298264]
    S2 gupdate1c98babdb7847b2;Google Update Service (gupdate1c98babdb7847b2);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 133104]
    S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
    S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2008-05-23 20160]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-09 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-10 13:15]

    2009-03-09 c:\windows\Tasks\GoogleUpdateTaskMachine.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 13:17]
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{070547D8-462D-4EA5-8F21-6C3F091E58CF} - (no file)
    BHO-{18936674-1CB3-4F4F-82C9-095F8446108D} - (no file)
    BHO-{29BDA8BF-5984-4E22-AF97-43830CA46962} - (no file)
    BHO-{5737F430-A65E-4E72-87E6-A7970F25A061} - (no file)
    BHO-{76bb1c6c-7593-4ff7-83ca-da48e9bc2c77} - c:\windows\system32\vuzrpg.dll
    BHO-{E57B841E-5469-4393-A139-3E7043EA973A} - (no file)
    Notify-cbXQKBRJ - (no file)
    Notify-ssqRhhFx - (no file)


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uInternet Connection Wizard,ShellNext = yes
    uInternet Connection Wizard,ShellNext = 0a000000
    uInternet Connection Wizard,ShellNext = yes
    uInternet Connection Wizard,ShellNext = 01000000
    uInternet Connection Wizard,ShellNext = yes
    uInternet Connection Wizard,ShellNext = 1a000000
    uInternet Connection Wizard,ShellNext = 1a000000
    uInternet Connection Wizard,ShellNext = Microsoft Corporation
    uInternet Connection Wizard,ShellNext = MICROSO
    uInternet Connection Wizard,ShellNext = 6.0.2600.0000
    uInternet Connection Wizard,ShellNext = \0
    uInternet Connection Wizard,ShellNext = about:NoAdd-ons
    uInternet Connection Wizard,ShellNext = about:SecurityRisk
    uInternet Connection Wizard,ShellNext = no
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-08 19:21:20
    Windows 5.1.2600 Service Pack 3 NTFS

    detected NTDLL code modification:
    ZwClose, ZwOpenFile

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-746137067-813497703-725345543-1004\Software\SecuROM\License information*]
    "datasecu"=hex:c1,45,eb,14,87,d7,c5,76,63,e2,54,91,49,4c,c4,7f,bf,d1,00,0e,78,
    28,af,c1,90,7c,69,06,32,09,57,4c,a6,f1,5d,94,b3,fa,9a,d8,d1,25,9a,15,87,94,\
    "rkeysecu"=hex:e6,01,ea,ac,60,05,c2,ba,bb,b0,d8,7a,b5,50,8d,da
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(940)
    c:\windows\system32\guard32.dll

    - - - - - - - > 'lsass.exe'(1000)
    c:\windows\system32\guard32.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
    c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    c:\program files\Lavasoft\Ad-Aware\aawservice.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\program files\AVG\AVG8\avgcsrvx.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\rundll32.exe
    c:\windows\system32\rundll32.exe
    c:\windows\system32\rundll32.exe
    c:\docume~1\Amiee\LOCALS~1\temp\RtkBtMnt.exe
    c:\windows\system32\wbem\wmiadap.exe
    .
    **************************************************************************
    .
    Completion time: 2009-03-08 19:25:20 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-03-09 00:25:16
    ComboFix2.txt 2009-02-07 15:53:07

    Pre-Run: 123,925,839,872 bytes free
    Post-Run: 124,129,849,344 bytes free

    517 --- E O F --- 2009-02-26 18:18:30



    And the hjt log:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:33:44 PM, on 3/8/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\DOCUME~1\Amiee\LOCALS~1\Temp\RtkBtMnt.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: (no name) - {d1b951a2-6748-44bc-8793-269e233ece52} - C:\WINDOWS\system32\zibuyubo.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\WINDOWS\PLFSet.dll,PLFDefSetting
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [voduwakuso] Rundll32.exe "C:\WINDOWS\system32\jutepeso.dll",s
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
    O4 - HKLM\..\Run: [70f5d722] rundll32.exe "C:\WINDOWS\system32\toyoyavi.dll",b
    O4 - HKLM\..\Run: [CPM73c6e4be] Rundll32.exe "c:\windows\system32\toturobe.dll",a
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1211556379173
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1211556454969
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSC...ws-i586-jc.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{31CE2B33-6824-4BF1-8F53-2EDB8B51F57B}: NameServer = 69.78.96.14 66.174.92.14
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\kapekabo.dll c:\windows\system32\toturobe.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\toturobe.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\toturobe.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    O23 - Service: Google Update Service (gupdate1c98babdb7847b2) (gupdate1c98babdb7847b2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 8976 bytes

  4. #4
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    TeaTimer is still active. Please disable it as instructed before.

    After that:

    Open notepad and copy/paste the text in the codebox below into it:

    Code:
    File::
    c:\windows\system32\toturobe.dll
    c:\windows\system32\dinizuha.dll
    c:\windows\system32\zelayira.dll
    c:\windows\system32\toyoyavi.dll
    c:\windows\system32\jutepeso.dll
    c:\windows\system32\zibuyubo.dll
    c:\windows\system32\kapekabo.dll
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Junior Member
    Join Date
    Feb 2009
    Posts
    11

    Default

    here is the updated combofix log:

    ComboFix 09-03-06.02 - Amiee 2009-03-09 18:45:07.3 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1791.1320 [GMT -5:00]
    Running from: c:\documents and settings\Amiee\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Amiee\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
    * Created a new restore point

    FILE ::
    c:\windows\system32\dinizuha.dll
    c:\windows\system32\jutepeso.dll
    c:\windows\system32\kapekabo.dll
    c:\windows\system32\toturobe.dll
    c:\windows\system32\toyoyavi.dll
    c:\windows\system32\zelayira.dll
    c:\windows\system32\zibuyubo.dll
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\dinizuha.dll
    c:\windows\system32\ivayoyot.ini
    c:\windows\system32\jutepeso.dll
    c:\windows\system32\toturobe.dll
    c:\windows\system32\toyoyavi.dll
    c:\windows\system32\zelayira.dll
    c:\windows\system32\zibuyubo.dll

    .
    ((((((((((((((((((((((((( Files Created from 2009-02-09 to 2009-03-09 )))))))))))))))))))))))))))))))
    .

    2009-03-09 10:35 . 2009-03-09 10:35 2,713 ---hs---- c:\windows\system32\rasawofu.dll
    2009-03-09 10:35 . 2009-03-09 10:35 2,713 ---hs---- c:\windows\system32\mayonibe.dll
    2009-03-09 10:35 . 2009-03-09 10:35 2,713 ---hs---- c:\windows\system32\lulakodu.dll
    2009-03-08 15:01 . 2009-03-08 15:01 10,240 --a------ c:\windows\instsp1.exe
    2009-03-07 12:12 . 2009-03-09 18:43 <DIR> d-------- c:\program files\COMODO
    2009-03-07 12:12 . 2009-03-09 18:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Comodo
    2009-03-07 11:27 . 2009-03-07 11:40 324 --a------ c:\windows\wininit.ini
    2009-02-21 15:29 . 2009-02-21 15:29 <DIR> d-------- c:\program files\AGD Interactive
    2009-02-21 13:12 . 2009-02-21 13:12 <DIR> d-------- c:\program files\IA
    2009-02-10 13:15 . 2009-03-08 22:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Google Updater

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-07 16:40 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-03-06 02:06 --------- d-----w c:\program files\SpywareBlaster
    2009-03-03 17:02 --------- d-----w c:\program files\World of Warcraft
    2009-02-26 19:32 --------- d-----w c:\program files\Microsoft Silverlight
    2009-02-15 05:49 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-02-15 05:48 --------- d-----w c:\program files\Spybot - Search & Destroy
    2009-02-12 03:41 --------- d-----w c:\program files\Google
    2009-02-10 19:19 --------- d-----w c:\program files\Picasa2
    2009-02-08 13:47 --------- d-----w c:\program files\Java
    2009-02-07 15:35 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
    2009-02-04 05:14 --------- d-----w c:\program files\Trend Micro
    2009-02-04 05:13 --------- d-----w c:\program files\ERUNT
    2009-02-01 17:14 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
    2009-02-01 17:14 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
    2009-01-10 19:07 --------- d-----w c:\documents and settings\Amiee\Application Data\Winamp
    .

    ((((((((((((((((((((((((((((( SnapShot_2009-03-08_19.23.47.45 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-09\ERDNT.EXE
    + 2009-03-09 23:49:07 7,307,264 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-09\Users\00000001\NTUSER.DAT
    + 2009-03-09 23:49:07 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-09\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-9-2009\ERDNT.EXE
    + 2009-03-09 14:34:23 7,307,264 ----a-w c:\windows\ERDNT\AutoBackup\3-9-2009\Users\00000001\NTUSER.DAT
    + 2009-03-09 14:34:23 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-9-2009\Users\00000002\UsrClass.dat
    - 2009-03-08 16:09:21 63,590 ----a-w c:\windows\system32\perfc009.dat
    + 2009-03-09 23:42:13 63,590 ----a-w c:\windows\system32\perfc009.dat
    - 2009-03-08 16:09:21 404,536 ----a-w c:\windows\system32\perfh009.dat
    + 2009-03-09 23:42:13 404,536 ----a-w c:\windows\system32\perfh009.dat
    + 2009-03-09 23:48:45 16,384 ----atw c:\windows\temp\Perflib_Perfdata_5e8.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-23 8433664]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-23 81920]
    "PLFSet"="c:\windows\PLFSet.dll" [2007-04-24 45056]
    "RoxioDragToDisc"="c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2004-06-24 1691648]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-01 1601304]
    "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
    "nwiz"="nwiz.exe" [2007-07-23 c:\windows\system32\nwiz.exe]
    "RTHDCPL"="RTHDCPL.EXE" [2007-07-23 c:\windows\RTHDCPL.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

    c:\documents and settings\Amiee\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-02-01 12:14 10520 c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXQKBRJ]
    [BU]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqRhhFx]
    [BU]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
    backup=c:\windows\pss\Bluetooth.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-23 325128]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-05-23 107272]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-06 903960]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-06 298264]
    S2 gupdate1c98babdb7847b2;Google Update Service (gupdate1c98babdb7847b2);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 133104]
    S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
    S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2008-05-23 20160]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-09 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-10 13:15]

    2009-03-09 c:\windows\Tasks\GoogleUpdateTaskMachine.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 13:17]
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{d1b951a2-6748-44bc-8793-269e233ece52} - c:\windows\system32\zibuyubo.dll
    HKLM-Run-voduwakuso - c:\windows\system32\jutepeso.dll
    HKLM-Run-70f5d722 - c:\windows\system32\toyoyavi.dll
    HKLM-Run-CPM73c6e4be - c:\windows\system32\toturobe.dll


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-09 18:48:55
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-746137067-813497703-725345543-1004\Software\SecuROM\License information*]
    "datasecu"=hex:c1,45,eb,14,87,d7,c5,76,63,e2,54,91,49,4c,c4,7f,bf,d1,00,0e,78,
    28,af,c1,90,7c,69,06,32,09,57,4c,a6,f1,5d,94,b3,fa,9a,d8,d1,25,9a,15,87,94,\
    "rkeysecu"=hex:e6,01,ea,ac,60,05,c2,ba,bb,b0,d8,7a,b5,50,8d,da
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    c:\program files\Lavasoft\Ad-Aware\aawservice.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\program files\AVG\AVG8\avgcsrvx.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\rundll32.exe
    c:\docume~1\Amiee\LOCALS~1\temp\RtkBtMnt.exe
    .
    **************************************************************************
    .
    Completion time: 2009-03-09 18:52:00 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-03-09 23:51:58
    ComboFix2.txt 2009-03-09 00:25:23
    ComboFix3.txt 2009-02-07 15:53:07

    Pre-Run: 123,952,283,648 bytes free
    Post-Run: 124,135,030,784 bytes free

    178 --- E O F --- 2009-02-26 18:18:30


    And here is the latest hjt log, I made double sure that teatime was off this time.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:53:36 PM, on 3/9/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\DOCUME~1\Amiee\LOCALS~1\Temp\RtkBtMnt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\WINDOWS\PLFSet.dll,PLFDefSetting
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1211556379173
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1211556454969
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSC...ws-i586-jc.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O20 - Winlogon Notify: cbXQKBRJ - C:\WINDOWS\
    O20 - Winlogon Notify: ssqRhhFx - C:\WINDOWS\
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Google Update Service (gupdate1c98babdb7847b2) (gupdate1c98babdb7847b2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 7699 bytes

  6. #6
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Open notepad and copy/paste the text in the codebox below into it:

    Code:
    File::
    c:\windows\system32\rasawofu.dll
    c:\windows\system32\mayonibe.dll
    c:\windows\system32\lulakodu.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXQKBRJ]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqRhhFx]
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #7
    Junior Member
    Join Date
    Feb 2009
    Posts
    11

    Default

    the combofix log:

    ComboFix 09-03-10.01 - Amiee 2009-03-10 18:45:07.4 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1791.1290 [GMT -5:00]
    Running from: c:\documents and settings\Amiee\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Amiee\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
    * Created a new restore point

    FILE ::
    c:\windows\system32\lulakodu.dll
    c:\windows\system32\mayonibe.dll
    c:\windows\system32\rasawofu.dll
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\lulakodu.dll
    c:\windows\system32\mayonibe.dll
    c:\windows\system32\rasawofu.dll

    .
    ((((((((((((((((((((((((( Files Created from 2009-02-10 to 2009-03-10 )))))))))))))))))))))))))))))))
    .

    2009-03-10 18:42 . 2009-03-10 18:42 <DIR> d-------- c:\windows\LastGood
    2009-03-08 15:01 . 2009-03-08 15:01 10,240 --a------ c:\windows\instsp1.exe
    2009-03-07 12:12 . 2009-03-09 18:43 <DIR> d-------- c:\program files\COMODO
    2009-03-07 12:12 . 2009-03-09 18:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Comodo
    2009-03-07 11:27 . 2009-03-07 11:40 324 --a------ c:\windows\wininit.ini
    2009-02-21 15:29 . 2009-02-21 15:29 <DIR> d-------- c:\program files\AGD Interactive
    2009-02-21 13:12 . 2009-02-21 13:12 <DIR> d-------- c:\program files\IA
    2009-02-10 13:15 . 2009-03-09 23:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Google Updater

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-07 16:40 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-03-06 02:06 --------- d-----w c:\program files\SpywareBlaster
    2009-03-03 17:02 --------- d-----w c:\program files\World of Warcraft
    2009-02-26 19:32 --------- d-----w c:\program files\Microsoft Silverlight
    2009-02-15 05:49 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-02-15 05:48 --------- d-----w c:\program files\Spybot - Search & Destroy
    2009-02-12 03:41 --------- d-----w c:\program files\Google
    2009-02-10 19:19 --------- d-----w c:\program files\Picasa2
    2009-02-08 13:47 410,984 ----a-w c:\windows\system32\deploytk.dll
    2009-02-08 13:47 --------- d-----w c:\program files\Java
    2009-02-07 15:35 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
    2009-02-04 05:14 --------- d-----w c:\program files\Trend Micro
    2009-02-04 05:13 --------- d-----w c:\program files\ERUNT
    2009-02-01 17:14 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
    2009-02-01 17:14 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
    2009-02-01 17:14 10,520 ----a-w c:\windows\system32\avgrsstx.dll
    2009-01-10 19:07 --------- d-----w c:\documents and settings\Amiee\Application Data\Winamp
    2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
    .

    ((((((((((((((((((((((((((((( SnapShot_2009-03-08_19.23.47.45 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-09\ERDNT.EXE
    + 2009-03-09 23:49:07 7,307,264 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-09\Users\00000001\NTUSER.DAT
    + 2009-03-09 23:49:07 159,744 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-09\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-10-2009\ERDNT.EXE
    + 2009-03-10 13:40:40 7,307,264 ----a-w c:\windows\ERDNT\AutoBackup\3-10-2009\Users\00000001\NTUSER.DAT
    + 2009-03-10 13:40:40 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-10-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-9-2009\ERDNT.EXE
    + 2009-03-09 14:34:23 7,307,264 ----a-w c:\windows\ERDNT\AutoBackup\3-9-2009\Users\00000001\NTUSER.DAT
    + 2009-03-09 14:34:23 159,744 ----a-w c:\windows\ERDNT\AutoBackup\3-9-2009\Users\00000002\UsrClass.dat
    - 2009-03-08 16:09:21 63,590 ----a-w c:\windows\system32\perfc009.dat
    + 2009-03-10 23:40:48 63,590 ----a-w c:\windows\system32\perfc009.dat
    - 2009-03-08 16:09:21 404,536 ----a-w c:\windows\system32\perfh009.dat
    + 2009-03-10 23:40:48 404,536 ----a-w c:\windows\system32\perfh009.dat
    + 2009-03-10 23:36:30 16,384 ----atw c:\windows\temp\Perflib_Perfdata_7f4.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-23 8433664]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-23 81920]
    "PLFSet"="c:\windows\PLFSet.dll" [2007-04-24 45056]
    "RoxioDragToDisc"="c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2004-06-24 1691648]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-01 1601304]
    "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
    "nwiz"="nwiz.exe" [2007-07-23 c:\windows\system32\nwiz.exe]
    "RTHDCPL"="RTHDCPL.EXE" [2007-07-23 c:\windows\RTHDCPL.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

    c:\documents and settings\Amiee\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-02-01 12:14 10520 c:\windows\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
    backup=c:\windows\pss\Bluetooth.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-23 325128]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-05-23 107272]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-06 903960]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-06 298264]
    S2 gupdate1c98babdb7847b2;Google Update Service (gupdate1c98babdb7847b2);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 133104]
    S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
    S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2008-05-23 20160]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-10 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-10 13:15]

    2009-03-10 c:\windows\Tasks\GoogleUpdateTaskMachine.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 13:17]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    TCP: {31CE2B33-6824-4BF1-8F53-2EDB8B51F57B} = 69.78.96.14 66.174.92.14
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-10 18:46:51
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-746137067-813497703-725345543-1004\Software\SecuROM\License information*]
    "datasecu"=hex:c1,45,eb,14,87,d7,c5,76,63,e2,54,91,49,4c,c4,7f,bf,d1,00,0e,78,
    28,af,c1,90,7c,69,06,32,09,57,4c,a6,f1,5d,94,b3,fa,9a,d8,d1,25,9a,15,87,94,\
    "rkeysecu"=hex:e6,01,ea,ac,60,05,c2,ba,bb,b0,d8,7a,b5,50,8d,da
    .
    Completion time: 2009-03-10 18:48:07
    ComboFix-quarantined-files.txt 2009-03-10 23:48:05
    ComboFix2.txt 2009-03-09 23:52:01
    ComboFix3.txt 2009-03-09 00:25:23
    ComboFix4.txt 2009-02-07 15:53:07

    Pre-Run: 123,999,010,816 bytes free
    Post-Run: 124,057,481,216 bytes free

    152 --- E O F --- 2009-02-26 18:18:30


    and the new hjt log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:50:45 PM, on 3/10/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\system32\imapi.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\WINDOWS\PLFSet.dll,PLFDefSetting
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1211556379173
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1211556454969
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSC...ws-i586-jc.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{31CE2B33-6824-4BF1-8F53-2EDB8B51F57B}: NameServer = 69.78.96.14 66.174.92.14
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Google Update Service (gupdate1c98babdb7847b2) (gupdate1c98babdb7847b2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 7650 bytes

  8. #8
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please go to Kaspersky website and perform an online antivirus scan.

    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select ''Run as administrator'' to perform this scan.

    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the results. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply along with a fresh HijackThis log.


    If you need a tutorial, see here
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #9
    Junior Member
    Join Date
    Feb 2009
    Posts
    11

    Default

    alright, here is the kaspersky log:

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7 REPORT
    Thursday, March 12, 2009
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Friday, March 13, 2009 02:18:18
    Records in database: 1893268
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    C:\
    D:\

    Scan statistics:
    Files scanned: 69860
    Threat name: 1
    Infected objects: 3
    Suspicious objects: 0
    Duration of the scan: 01:08:33


    File name / Threat name / Threats count
    C:\Qoobox\Quarantine\C\WINDOWS\system32\senekalespwmet.dll.vir Infected: Packed.Win32.Tdss.c 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\senekankfpqcxu.dll.vir Infected: Packed.Win32.Tdss.c 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\senekasipfviqx.dll.vir Infected: Packed.Win32.Tdss.c 1

    The selected area was scanned.


    and the fresh hjt log:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:14:44 AM, on 3/14/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\DOCUME~1\Amiee\LOCALS~1\Temp\RtkBtMnt.exe
    C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\WINDOWS\PLFSet.dll,PLFDefSetting
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1211556379173
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1211556454969
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSC...ws-i586-jc.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{31CE2B33-6824-4BF1-8F53-2EDB8B51F57B}: NameServer = 69.78.96.14 66.174.92.14
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Google Update Service (gupdate1c98babdb7847b2) (gupdate1c98babdb7847b2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 7700 bytes

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Empty this folder:

    C:\Qoobox\Quarantine

    Empty Recycle Bin.

    Still problems?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •